Skip to content Skip to footer

PRIVACY POLICY

1. Introduction And Purpose

Dinner Club Network Ltd (DCN) is committed to protecting the privacy and confidentiality of personal data processed within its operations. This Privacy Policy outlines how DCN collects, processes, stores, and protects personal data in compliance with the General Data Protection Regulation (GDPR) and the UK Data Protection Act 2018.

2. Scope

This policy applies to all personal data processed by DCN, including customer data, employee records, supplier information, and any other personally identifiable data related to DCN’s business activities. The Board of Directors is responsible for ensuring compliance with this policy.

3. Data Protection Principles

DCN will abide by the following principles when processing personal data:

  • Lawfulness, Fairness, and Transparency: Data will be processed lawfully and transparently.
  • Purpose Limitation: Data will only be used for specified, explicit, and legitimate purposes.
  • Data Minimisation: Only data necessary for the intended purpose will be processed.
  • Accuracy: Data will be kept accurate and up-to-date.
  • Storage Limitation: Data will only be stored as long as necessary for the purpose.
  • Integrity and Confidentiality: Data will be processed securely to prevent unauthorizedaccess, loss, or damage.

4. Data Subject Rights

Individuals have the following rights under this policy:

  • Right to be informed
  • Right of access
  • Right to rectification
  • Right to erasure (Right to be forgotten)
  • Right to restrict processing
  • Right to data portability
  • Right to object to processing
  • Rights concerning automated decision-making and profiling

5. Data Collection And Processing

DCN collects and processes personal data lawfully and fairly, ensuring that individuals are informed of how their data will be used, including:

  • Employment records
  • Customer and supplier information
  • Business contact information

6. Data Security And Confidentiality

DCN employs technical and organizational measures to protect personal data from breaches, including access controls, encryption, data anonymization, and secure storage.

7. Data Breaches

In the event of a data breach, DCN will follow its breach management procedures, including notifying relevant authorities within 72 hours if required and informing affected individuals promptly.

8. Data Retention And Disposal

Data will be retained according to DCN’s Records Retention Schedule and securely disposed of when no longer required.

9. Third-party Data Sharing

Personal data may only be shared with approved third parties under strict confidentiality agreements and for legitimate business purposes.

10. Governance And Acountibility

The Board of Directors is responsible for implementing and monitoring compliance with this policy. Regular audits and reviews will ensure continuous compliance and improvements.

11. Review And Upadtes

This policy will be reviewed annually or when significant changes occur in legal, regulatory, or operational circumstances.

Magdalena Cholewa
Director SQR Group – Board Member
06/12/2024

Go to Top